Bitbucket

Vendor:

First CVE: Apr 10, 2017 · Active for 9 years

20
Total CVEs
More Total CVEs than 94% of tracked products
3.3
Avg CVEs / Year
Higher CVE frequency than 82% of tracked products
7.4
Avg CVSS
Higher Avg CVSS than 48% of tracked products
5.0%
KEV Rate
Higher KEV Rate than 97% of tracked products

Trends Over Time

The number and severity of CVEs published that impact Bitbucket over time

Volume of CVEsAvg CVSS Base Score
First CVE
Apr 10, 2017
9 years ago
Most Recent CVE
Nov 17, 2022
1,347 days ago

CVE Severity & Scoring

Bitbucket20 CVEs
All CVEs352,713 CVEs
MediumHighCritical
Attack Vector
Local1 (5.0%)
Network19 (95.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low18 (90.0%)
High2 (10.0%)
Unknown0 (0.0%)
User Interaction
None18 (90.0%)
Unknown0 (0.0%)
Required2 (10.0%)
Privileges Required
Low12 (60.0%)
High1 (5.0%)
None7 (35.0%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (20 CVEs).

20 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Multiple API endpoints in Atlassian Bitbucket Server and Data Center 7.0.0 before version 7.6.17, from version 7.7.0 before version 7.17.10, from version 7.18.0 before version 7.21
Aug 25, 20228.899YESYES
There is a command injection vulnerability using environment variables in Bitbucket Server and Data Center. An attacker with permission to control their username can exploit this i
Nov 17, 20229.888NOYES
A vulnerability in multiple Atlassian products allows a remote, unauthenticated attacker to bypass Servlet Filters used by first and third party apps. The impact depends on which f
Jul 20, 20229.834NONO
The commit diff rest endpoint in Bitbucket Server and Data Center before 5.16.10 (the fixed version for 5.16.x ), from 6.0.0 before 6.0.10 (the fixed version for 6.0.x), from 6.1.0
Sep 19, 20199.834NONO
In browser editing in Atlassian Bitbucket Server from version 4.13.0 before 5.4.8 (the fixed version for 4.13.0 through 5.4.7), 5.5.0 before 5.5.8 (the fixed version for 5.5.x), 5.
Mar 22, 20189.933NONO
Atlassian Bitbucket Data Center licensed instances starting with version 5.13.0 before 5.13.6 (the fixed version for 5.13.x), from 5.14.0 before 5.14.4 (fixed version for 5.14.x),
Jun 3, 20199.132NONO
A vulnerability in multiple Atlassian products allows a remote, unauthenticated attacker to cause additional Servlet Filters to be invoked when the application processes requests o
Jul 20, 20228.829NONO
Bitbucket Server and Bitbucket Data Center versions starting from 1.0.0 before 5.16.11, from version 6.0.0 before 6.0.11, from version 6.1.0 before 6.1.9, from version 6.2.0 before
Jan 15, 20208.827NONO
Bitbucket Server and Bitbucket Data Center from version 4.13. before 5.16.11, from version 6.0.0 before 6.0.11, from version 6.1.0 before 6.1.9, from version 6.2.0 before 6.2.7, fr
Jan 15, 20208.826NONO
Bitbucket Server and Bitbucket Data Center versions starting from version 3.0.0 before version 5.16.11, from version 6.0.0 before 6.0.11, from version 6.1.0 before 6.1.9, from vers
Jan 15, 20208.826NONO

Exploit Exposure

Signals from CVEs in this product scope (20 CVEs).

CISA KEV
1 CVE
5.0% of CVEs· 97th percentile
Metasploit
2 CVEs
10.0% of CVEs· 97th percentile
Nuclei
1 CVE
5.0% of CVEs· 97th percentile
ExploitDB
1 CVE
5.0% of CVEs· 88th percentile

Social Chatter

Signals from CVEs in this product scope (20 CVEs).

Media Mentions

Signals from CVEs in this product scope (20 CVEs).

Top CNAs Publishing CVEs For Bitbucket

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
8.3.018.899.1%11
8.1.029.33.6%00
8.0.029.33.6%00
5.5.616.51.3%00
5.5.516.51.3%00
5.5.416.51.3%00
5.5.316.51.3%00
5.5.216.51.3%00
5.5.016.51.3%00